CVE-2013-6621 is a use-after-free vulnerability in Google Chrome versions prior to 31.0.1650.48, affecting various Debian, Google, and openSUSE Chrome distributions. This flaw, related to the x-webkit-speech attribute in text INPUT elements, allows remote attackers to trigger a denial of service or potentially achieve other unspecified impacts. With a CVSS score of 7.5, it poses a significant risk due to its low attack complexity and potential for partial confidentiality, integrity, and availability compromise. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not listed in CISA's KEV catalog, there is limited community discussion and media coverage, suggesting it has not seen widespread active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.2CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.2:*:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:* | ||
13.1CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:* | ||
<= 31.0.1650.47CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
31.0.1650.0CPE matchmatch criteria | cpe:2.3:a:google:chrome:31.0.1650.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.